Do you have VT intelligence and can see the content tab?
Because that shows the malicious powershell string. I assume they see that string in the browser. It's an FP in the sense that it detects the string in the wrong context.
I tried to talk to live chat but they ask me if I'm working with an infected bin I should not do it and therefore that's an infection, I tried to say that I'm not working on it and it's just an upload on VT which I just see it, I didn't make the upload, but they don't understand it.
Do you have VT intelligence and can see the content tab?
Because that shows the malicious powershell string. I assume they see that string in the browser. It's an FP in the sense that it detects the string in the wrong context.